Junglewise Threat Intelligence

CVE-2017-16023: decamelize regular expression denial of service

CVE-2017-16023 · Severity: low · CVSS 3 · Published 2018-07-24

Vendors: npm.

Executive brief

decamelize is a JavaScript library that converts camelCase strings into kebab-case format. The library is vulnerable to regular expression denial of service (ReDoS) attacks when processing untrusted input, allowing an attacker to cause the application to hang or consume excessive CPU resources by supplying specially crafted strings.

Technical details

The vulnerability is a regular expression denial of service (ReDoS, CWE-400) caused by an unvalidated separator parameter being passed directly into a regex pattern without proper escaping. When a user supplies a special regex metacharacter (such as the pipe "|") as the separator argument, it creates a malicious regular expression that exhibits catastrophic backtracking. An attacker can trigger this via network if the affected library processes user input without sanitization. The vulnerability affects versions 1.1.0 through 1.1.1; patched in version 1.1.2 and later.

Affected products

  • sindresorhus decamelize 1.1.0 through 1.1.1

Timeline

  • 2015-12-23: disclosed: Issue reported on GitHub
  • 2018-07-24: advisory: GHSA advisory published
  • 2017: patched: Fixed in version 1.1.2

References